Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Cloud sessions' shell commands that write this machine's Claude Code settings are held for the owner (tengu_violin_purfling)

Served Bash/PowerShell commands that write Claude Code settings files are denied or sent for approval, and auto mode cannot approve those asks

Group of 2 You'll notice Improvements
JSON All of v2.1.283
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
Remote ToolsArea: what it touches
ImprovementsKind: in v2.1.283,
What probably matters to youSection of the release

What

A served call is a tool call that a cloud session asks your machine to run for it. When the check is on, Claude Code now inspects served Bash or PowerShell commands for writes to this machine's own Claude Code settings files, or the folder that holds them:

  • It follows directory changes (cd, pushd), env and other wrapper words, and commands nested inside -c.
  • A command that definitely writes a settings file is refused. Nothing is run, and the model is told to make the change with the Edit or Write tool instead, so the change is held for the machine owner to review.
  • If Claude Code cannot work out everything the command writes, the call is sent to a person for approval (reason remote_call_unresolved_shell_write_ask).
  • Separately, an approval request raised by a settings-file safety check can no longer be approved automatically by the auto-mode classifier, the model that decides on permission requests in auto mode.

Both parts are controlled by the server flag tengu_violin_purfling, read in two places with different defaults. With no value from the server, the shell-write hold is off and the classifier exclusion is on. The classifier exclusion is lifted only if the server explicitly sends false. For this site's account and for an anonymous check, the flag server returned on, but no reading has been taken under this release yet.

Why

Without this, a remote session could use a shell command to rewrite the settings that decide its own permissions on your machine. Such changes now go through the tools the owner reviews, or to a person, instead of happening quietly.

Read from
Feature flag
tengu_violin_purfling On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.283: not a boolean we can read

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.283. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether the server turns on the shell-command hold for anyone, or whether the two different defaults are intended.
The name it cites is new in this buildNew in this build: tengu_violin_purfling

See this entry in the whole of v2.1.283 →

Feedback